Exploit discussion active in current signal (2 latest mentions)
Immediate actions
Patch openssl openssl systems immediately
Hunt for exploitation attempts and persistence artifacts
Increase monitoring for publicly documented tradecraft
Recommended action window: High priority (within 72h)
NVD description
Issue summary: PBMAC1 parameters in PKCS#12 files are missing validation
which can trigger a stack-based buffer overflow, invalid pointer or NULL
pointer dereference during MAC verification.
Impact summary: The stack buffer overflow or NULL pointer dereference may
cause a crash leading to Denial of Service for an application that parses
untrusted PKCS#12 files. The buffer overflow may also potentially enable
code execution depending on platform mitigations.
When verifying a PKCS#12 file that uses PBMAC1 for the MAC, the PBKDF2
salt and keylength parameters from the file are used without validation.
If the value of keylength exceeds the size of the fixed stack buffer used
for the derived key (64 bytes), the key derivation will overflow the buffer.
The overflow length is attacker-controlled. Also, if the salt parameter is
not an OCTET STRING type this can lead to invalid or NULL pointer
dereference.
Exploiting this issue requires a user or application to process
a maliciously crafted PKCS#12 file. It is uncommon to accept untrusted
PKCS#12 files in applications as they are usually used to store private
keys which are trusted by definition. For this reason the issue was assessed
as Moderate severity.
The FIPS modules in 3.6, 3.5 and 3.4 are not affected by this issue, as
PKCS#12 processing is outside the OpenSSL FIPS module boundary.
OpenSSL 3.6, 3.5 and 3.4 are vulnerable to this issue.
OpenSSL 3.3, 3.0, 1.1.1 and 1.0.2 are not affected by this issue as they do
not support PBMAC1 in PKCS#12.
OpenSSL Security Advisory 27th January 2026 https://www.openwall.com/lists/oss-security/2026/01/27/7
12 CVEs, 2 stack-based buffer overflows
CVE-2025-15467 Stack buffer overflow in CMS AuthEnvelopedData parsing (High)
CVE-2025-11187 Improper validation of PBMAC1 parameters in PKCS#12 MAC verification (Moderate)
Post summary
OpenSSL advisory from Jan 27, 2026 announces 12 CVEs, including two stack buffer overflows, but provides no PoC, exploit, or patch details, merely technical classifications and severity ratings.
Kusanagi's OpenSSL module update to 3.5.5‑1 includes fixes for CVE‑2025‑11187 and CVE‑2025‑15469, which can be applied with "dnf upgrade" and the release link.
The article announces that OpenSSL CVE‑2025‑11187 and other high‑severity vulnerabilities have been patched. No exploit or active‑exploitation details are provided.
The article announces that OpenSSL has released patches for multiple high‑severity vulnerabilities, including CVE-2025-11187, and directs readers to further details via the provided link.
🚨 OpenSSL Patches 12 Flaws, Including High-Severity Parsing Bugs That Could Enable RCE
OpenSSL released updates fixing 12 vulnerabilities, including two high-severity stack buffer overflows (CVE-2025-15467 in CMS/PKCS#7 AEAD parsing and CVE-2025-11187 in PKCS#12 PBMAC1 processing) that can cause DoS and may be exploitable for remote code execution in certain scenarios. Most remaining issues are low-severity parsing/robustness bugs (NULL deref, OOB write/type confusion) and should be patched quickly where OpenSSL processes untrusted inputs.
🎯 Target: Global/Cryptography (OpenSSL users)
#️⃣ Category: #Vulnerability#BlueTeam
🔗 URL: https://www.scworld.com/brief/openssl-patches-12-vulnerabilities-including-high-severity-rce-flaw
Post summary
OpenSSL has issued patches for 12 CVEs, including two high‑severity buffer overflows that could allow remote code execution; users are urged to apply the updates promptly.
🚨 CVE-2025-11187 : OPENSSL PKCS#12 PBMAC1 STACK BUFFER OVERFLOW ALERT 🚨
@openssl_
A vulnerability has been disclosed in OpenSSL’s PKCS#12 verification — where parsing a crafted PKCS#12 (.p12/.pfx) using PBMAC1 can lead to a stack-based buffer overflow / crash, and in some conditions may be exploitable for code execution (platform- and hardening-dependent).
Risk Severity: Moderate (OpenSSL rating); public PoC exists; risk increases materially for services that process untrusted PKCS#12 uploads/imports.
Impact:
• Denial of Service (crash) in applications that parse attacker-supplied PKCS#12 files[ citation:3]
• Potential code execution in worst-case scenarios depending on mitigations (stack canaries/ASLR/NX and app context)
• Credential-handling pipeline disruption (certificate management, VPN user bundle imports, S/MIME tooling)
• Secondary failure modes reported include invalid/NULL pointer dereference paths (reliable crash primitives)
Root Cause:
CWE-120 (Buffer Copy without Checking Size of Input) / CWE-130 (Improper Handling of Length Parameter Inconsistency)
When verifying a PKCS#12 file that uses PBMAC1 for the MAC, OpenSSL uses PBKDF2 parameters from the file (salt and keylength) without sufficient validation, which can drive unsafe writes into fixed-size stack buffers in the verification routine.
Attackers can:
• Deliver a malicious .p12/.pfx to any workflow that imports/validates PKCS#12 from external sources (uploads, email gateways, certificate portals, VPN enrollment)
• Ensure the PKCS#12 uses PBMAC1 so the vulnerable verification path is exercised[ citation:3]
• Trigger a stack overflow via attacker-controlled PBKDF2 keylength / malformed salt fields, crashing the process and potentially enabling exploitation in favorable conditions[ citation:3]
• Repeatedly crash certificate-processing services for sustained DoS (and attempt exploitation where feasible)
Are You Affected?
Vulnerable:
• OpenSSL 3.4.0, 3.5.0, 3.6.0 (per advisory/tracker guidance; depends on PBMAC1 usage path in PKCS#12 verification).
• Highest risk where PKCS#12 is processed from untrusted sources (uploads/imports/automated ingestion).
Fixed in:
• OpenSSL 3.4.1, 3.5.1, and 3.6.1+ (branch fixes released in the January 2026 advisory window).
Note: Many environments assume PKCS#12 files are “trusted admin input.” If your product accepts PKCS#12 from users/partners/customers, treat this as a materially higher risk than the “Moderate” label implies.
Immediate Action Required:
Update/Patch:
• Upgrade to OpenSSL 3.4.1 / 3.5.1 / 3.6.1+ (choose the fixed release for your current branch) or apply your OS/vendor backport.
Mitigation (if patching is delayed):
• Restrict/disable PKCS#12 import/upload features where feasible; gate imports behind admin-only workflows.
• Add strict validation controls: file size limits, content-type enforcement, and isolate PKCS#12 parsing into a sandboxed/helper process (blast-radius reduction).
Audit & Monitor:
• Monitor for crashes/SEGV in certificate-handling components and OpenSSL error patterns tied to pkcs12 verification.
• Identify all services that parse .p12/.pfx (web portals, VPN tooling, PKI automation, email/S/MIME workflows).
Incident Response:
• If you suspect exploitation attempts: isolate affected services, preserve crash dumps/logs, and review PKCS#12 ingestion sources. If compromise is suspected, rotate impacted secrets/keys and rebuild from known-good baselines.
If you process untrusted PKCS#12 anywhere, prioritize patching—this is a memory safety bug with public PoC, and the most realistic near-term outcome is reliable DoS, with RCE risk dependent on environment hardening. 🛡️
Post summary
The advisory discloses CVE-2025-11187, a stack buffer overflow in OpenSSL’s PKCS#12 PBMAC1 verification, provides a public PoC, detailed technical info, and patch and mitigation guidance.
🚨 OpenSSL Patches 12 Flaws Including High-Severity Pre-Auth RCE Risks in CMS/PKCS#12 Parsing
OpenSSL released fixes for 12 vulnerabilities, with the most serious being CVE-2025-15467 (stack overflow in CMS AuthEnvelopedData AEAD IV parsing, affecting OpenSSL 3.0–3.6) and CVE-2025-11187 (PBMAC1 parameter validation leading to stack overflow during PKCS#12 MAC verification, affecting 3.4–3.6), both potentially enabling DoS and under certain conditions remote code execution when parsing untrusted inputs.
🎯 Target: Global/Software Supply Chain (OpenSSL Consumers)
#️⃣ Category: #Vulnerability#BlueTeam
🔗 URL: https://securityaffairs.com/187445/security/openssl-issued-security-updates-to-fix-12-flaws-including-remote-code-execution.html
Post summary
OpenSSL has issued patches for 12 vulnerabilities, including two high‑severity CVEs (CVE‑2025‑15467 and CVE‑2025‑11187) that could allow remote code execution via CMS/PKCS#12 parsing, and the article announces these fixes.
kusanagi-openssl Module Update 3.5.5-1
KUSANAGI 9 modules have been updated.
The updated modules are as follows:
openssl
3.5.5-1
This update includes support for vulnerability(CVE-2025-11187, CVE-2025-15469).
The module update can be applied...
https://kusanagi.tokyo/en/releases/22846/
Post summary
KUSANAGI released an OpenSSL module update (3.5.5-1) that patches CVE-2025-11187 and CVE-2025-15469, providing a fix for the affected component.
🚨 OpenSSL Patches 12 Bugs Including High-Severity RCE-Grade Overflows in CMS/PKCS#12 Parsing
OpenSSL’s Jan 27, 2026 security release fixes 12 vulnerabilities, including a High-severity stack overflow in CMS AuthEnvelopedData parsing (CVE-2025-15467) and a Moderate PKCS#12 PBMAC1 parameter-validation bug (CVE-2025-11187) that can crash apps and may enable code execution depending on mitigations. Upgrade to patched releases (e.g., 3.6.1 / 3.5.5 / 3.4.4, plus 3.3.6 and 3.0.19 where applicable) and treat any workflow that parses untrusted CMS/PKCS#7 or PKCS#12 files as internet-facing attack surface.
🎯 Target: Global/Software & Supply Chain
#️⃣ Category: #Vulnerability#BlueTeam
🔗 URL: https://www.infosecurity-magazine.com/news/12-openssl-flaws/
Post summary
The article announces OpenSSL’s 12‑bug fix release, highlighting a high‑severity stack overflow in CMS parsing and a moderate PKCS#12 crash bug, and urges users to upgrade their OpenSSL versions to mitigate potential remote code execution.
🚨 OpenSSL patches critical CMS stack overflow (CVE-2025-15467) that can lead to pre-auth code execution
OpenSSL’s latest advisory fixes multiple flaws, led by CVE-2025-15467 where a crafted CMS AuthEnvelopedData message with an oversized AES-GCM IV can overflow a stack buffer before authentication, enabling crashes and potential RCE in apps that parse untrusted CMS/PKCS#7. Upgrade to 3.6.1 / 3.5.5 / 3.4.4 / 3.3.6 / 3.0.19 (and review PKCS#12/PBMAC1 handling via CVE-2025-11187) to reduce exposure.
🎯 Target: Global/Cryptographic Infrastructure (servers, S/MIME/CMS consumers)
#️⃣ Category: #Vulnerability#BlueTeam#CyberIntel
🔗 URL: https://cyberpress.org/openssl-vulnerabilities-remote-execute-malicious-code/
Post summary
OpenSSL has fixed a critical CMS stack overflow (CVE‑2025‑15467) that could lead to pre‑auth code execution; users should upgrade to the listed versions as no active exploitation or PoC is reported.
OpenSSL 3.6.1 Is Now Available with Important Security Patches and Bug Fixes
This release addresses CVE-2025-11187, CVE-2025-15467, CVE-2025-15469, CVE-2025-66199, CVE-2025-68160, CVE-2025-69418, and CVE-2025-69419. https://9to5linux.com/openssl-3-6-1-is-now-available-with-important-security-patches-and-bug-fixes
Post summary
The article announces the OpenSSL 3.6.1 release, highlighting that it contains patches for several CVEs.